On 6/29/21 6:43 PM, Mark Murphy wrote:
Google finally released some details about their "code transparency" solution
for dealing with mandatory App Bundles/Play App Signing for new apps:
https://developer.android.com/guide/app-bundle/code-transparency
And, FWIW, here are my initial thoughts on the subject:
https://commonsware.com/blog/2021/06/29/initial-thoughts-code-transparency.html
Thanks for the always thorough and thoughtful updates and analysis, Mark.
Wouldn't it be possible to build a library that we include in our apps
that inspects the APK files at runtime on a device, and looks for the
transparency files in the APK, and even checks the hashes. This could be
done as a "App Integrity Check" on first run.
+n
_______________________________________________
List info: https://lists.mayfirst.org/mailman/listinfo/guardian-dev
To unsubscribe, email: [email protected]